Главная
Study mode:
on
1
Introduction
2
Outline
3
About me
4
Research timeline
5
Why PHP
6
The problem
7
Static Code Analysis
8
Challenges
9
Approach Overview
10
Simulation
11
ObjectOriented Analysis
12
First Order Security Vulnerabilities
13
Security Mechanisms
14
Context Sensitive Change Analysis
15
Study Paper
16
Demo
17
Second Order Security Vulnerabilities
18
Persistent Data Store Detection
19
Gadget Chain Detection
20
PropertyOriented Programming
21
Object Injection
22
Detect Gadget Chains
23
Conclusion
24
Questions
Description:
Explore static code analysis techniques for identifying complex PHP application vulnerabilities in this 40-minute conference talk from AppSecEU 2016 in Rome. Delve into challenges, approach overviews, and advanced concepts such as first-order and second-order security vulnerabilities. Learn about simulation, object-oriented analysis, security mechanisms, context-sensitive change analysis, persistent data store detection, and gadget chain detection. Gain insights into property-oriented programming, object injection, and methods for detecting gadget chains. Conclude with a comprehensive understanding of static code analysis for PHP applications and participate in a Q&A session.

Static Code Analysis of Complex PHP Application Vulnerabilities

OWASP Foundation
Add to list